CVE-2024-0136
published 2025-01-28CVE-2024-0136: NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and…
PriorityP344high8.4CVSS 3.1
AVNACLPRHUIRSCCHIHAH
EPSS
0.66%
47.3th percentile
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| nvidia | nvidia_container_toolkit | < 1.17.3 | 1.17.3 |
| nvidia | nvidia_container_toolkit | — | — |
| nvidia | nvidia_gpu_operator | < 24.9.1 | 24.9.1 |
| nvidia | nvidia_gpu_operator | — | — |
CVSS provenance
nvdv3.18.4HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H
vendor_redhat7.6HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
nvidia-container-toolkit: Improper Isolation or Compartmentalization in NVIDIA Container Toolkit
vendor_redhat·2025-01-28·CVSS 7.6
CVE-2024-0136 [HIGH] CWE-653 nvidia-container-toolkit: Improper Isolation or Compartmentalization in NVIDIA Container Toolkit
nvidia-container-toolkit: Improper Isolation or Compartmentalization in NVIDIA Container Toolkit
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
An improper isolation vulnerability was found in the NVIDIA Container Toolkit, where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVID
GHSA
GHSA-vcfp-63cx-4h59: NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining
ghsa_unreviewed·2025-01-28
CVE-2024-0136 [HIGH] CWE-653 GHSA-vcfp-63cx-4h59: NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining
NVIDIA Container Toolkit contains an improper isolation vulnerability where a specially crafted container image could lead to untrusted code obtaining read and write access to host devices. This vulnerability is present only when the NVIDIA Container Toolkit is configured in a nondefault way. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges, information disclosure, and data tampering.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-01-28
Published